AMLEGALS — Strategic Lawyering
Knowledge Centre

Insights

Authoritative analysis on data privacy compliance under DPDPA 2023. Eighteen essential topics covering consent management, breach response, cross border transfers, penalties, DPO requirements, and emerging regulatory developments.

18 In-Depth Articles
240+ Minutes Reading
Statutory Cross-References
Consent Management Under DPDPA
Consent & Rights

Consent Management Under DPDPA

Building Compliant Consent Architecture for Digital Platforms

"Consent shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action."

— DPDPA Section 6

DPDPA Section 6DPDP Rules 2025 Rule 3+2
Data Breach Notification Under DPDPA
Breach Response

Data Breach Notification Under DPDPA

Navigating the 72-Hour Reporting Window and CERT-In Harmonisation

"Any service provider shall mandatorily report cyber incidents to CERT-In within 6 hours."

— CERT-In Directions 2022

DPDPA Section 8(6)CERT-In Directions April 2022+2
View Full Response Framework
Significant Data Fiduciary Obligations
Compliance

Significant Data Fiduciary Obligations

Enhanced Compliance Requirements for High-Volume Data Processors

"The Central Government may notify any Data Fiduciary as a Significant Data Fiduciary based on volume and sensitivity of personal data processed."

— DPDPA Section 10(1)

DPDPA Section 10DPDP Rules 2025 Rule 13+1
Cross-Border Data Transfers Under DPDPA
International

Cross-Border Data Transfers Under DPDPA

Navigating the Negative List Framework and Sectoral Localisation

"The Central Government may restrict transfer of personal data to such country or territory outside India as may be notified."

— DPDPA Section 17

DPDPA Section 17RBI Payment Data Localisation Circular+2
Processing Children's Data Under DPDPA
Children's Data

Processing Children's Data Under DPDPA

Verifiable Parental Consent and Prohibited Processing Activities

"The Data Fiduciary shall, before processing any personal data of a child, obtain verifiable consent of the parent of such child."

— DPDPA Section 9(1)

DPDPA Section 9DPDP Rules 2025 Rule 10+2
DPDPA for Online Gaming — Section 9 & Third Schedule
Dark Patterns and DPDPA Compliance
Consent & Rights

Dark Patterns and DPDPA Compliance

How Deceptive Design Practices Violate Data Protection Principles

"Consent must be free, informed, specific, and unambiguous—dark patterns directly contradict these requirements."

— DPDPA Compliance Principle

DPDPA Section 6Dark Patterns Guidelines 2023+2
Data Principal Rights Under DPDPA
Consent & Rights

Data Principal Rights Under DPDPA

Access, Correction, Erasure, and Grievance Redressal Obligations

"The Data Principal shall have the right to obtain from the Data Fiduciary confirmation whether personal data is being processed."

— DPDPA Section 11(1)

DPDPA Section 11DPDPA Section 12+3
Data Fiduciary Obligations Under DPDPA
Compliance

Data Fiduciary Obligations Under DPDPA

Understanding Primary Responsibility for Lawful Processing

"A Data Fiduciary is any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data."

— DPDPA Section 2(i)

DPDPA Section 2(i)DPDPA Section 6+3
DPDPA Implementation Timeline
Compliance

DPDPA Implementation Timeline

Navigating the 12-18 Month Compliance Runway

"The 18-month milestone represents a cliff edge—significant effort will be required for sanitizing legacy data."

— Implementation Advisory

DPDPA Commencement ProvisionsDPDP Rules 2025+2
DSA vs NDA vs MOU: Data Privacy Implications
Contracts

DSA vs NDA vs MOU: Data Privacy Implications

Choosing the Right Agreement for Personal Data Sharing

"When personal data is shared, a Data Sharing Agreement is mandatory under DPDPA—NDAs and MOUs are insufficient."

— Contractual Compliance Principle

DPDPA Section 8(2)DPDP Rules 2025 Rule 6+2
DPDPA Penalties and Fines Structure
Penalties

DPDPA Penalties and Fines Structure

Understanding the ₹250 Crore Maximum Penalty Framework

"The Data Protection Board may, after giving reasonable opportunity of being heard, impose a monetary penalty not exceeding ₹250 crores."

— DPDPA Section 33

DPDPA Section 33DPDPA The Schedule+2
Data Protection Officer Appointment Under DPDPA
Compliance

Data Protection Officer Appointment Under DPDPA

When and How to Appoint a Resident DPO in India

"A Significant Data Fiduciary shall appoint a Data Protection Officer who shall be based in India."

— DPDPA Section 10(2)(a)

DPDPA Section 10(2)(a)DPDP Rules 2025 Rule 13+2
DPDPA vs GDPR: Key Differences and Similarities
International

DPDPA vs GDPR: Key Differences and Similarities

Comparative Analysis for Multinational Compliance

"While DPDPA draws inspiration from GDPR, significant structural differences demand distinct compliance approaches."

— Comparative Analysis

DPDPA Section 2GDPR Article 3+3
Data Localisation Requirements in India
International

Data Localisation Requirements in India

Navigating DPDPA and Sectoral Localisation Mandates

"Data localisation in India operates through sector-specific regulations rather than DPDPA general mandate."

— Regulatory Framework

DPDPA Section 16RBI Circular on Payment Data 2018+2
Consent Manager Framework Under DPDPA
Consent & Rights

Consent Manager Framework Under DPDPA

Registration, Obligations, and Integration Requirements

"A Consent Manager shall be registered with the Board and shall act on behalf of a Data Principal."

— DPDPA Section 2(g)

DPDPA Section 2(g)DPDP Rules 2025 Rule 4+2
DPDPA for Consent Managers — Rule 4 Registration Advisory
Data Protection Impact Assessment Under DPDPA
Compliance

Data Protection Impact Assessment Under DPDPA

When and How to Conduct DPIAs for High-Risk Processing

"A Significant Data Fiduciary shall undertake Data Protection Impact Assessment."

— DPDPA Section 10(2)(c)

DPDPA Section 10(2)(c)DPDP Rules 2025 Rule 13+2
DPDPA Exemptions and Legitimate Uses
Compliance

DPDPA Exemptions and Legitimate Uses

When Consent is Not Required for Lawful Processing

"Personal data may be processed without consent for specified legitimate uses."

— DPDPA Section 7

DPDPA Section 7DPDPA Section 17+2
Personal Data Definition Under DPDPA
Definitions

Personal Data Definition Under DPDPA

Understanding What Constitutes Digital Personal Data

"Personal data means any data about an individual who is identifiable by or in relation to such data."

— DPDPA Section 2(t)

DPDPA Section 2(t)DPDPA Section 2(n)+2
Data Centre Operations Under DPDPA
Infrastructure

Data Centre Operations Under DPDPA

Navigating Processor Obligations, Localisation Requirements and Technical Compliance Standards

"The Data Processor shall process personal data only in accordance with the instructions of the Data Fiduciary and shall not process such personal data for any purpose other than the purpose for which it was provided."

— DPDPA Section 8(2)

DPDPA Section 2(k)DPDPA Section 8(2)+9
Grievance Redressal Under DPDPA
Compliance

Grievance Redressal Under DPDPA

Building Effective Internal Complaint Mechanisms Before the Data Protection Board Gets Involved

"Every Data Fiduciary shall publish the business contact information of a Data Protection Officer or such other person who is able to answer on behalf of the Data Fiduciary, the questions, if any, raised by the Data Principal about the processing of her personal data."

— DPDPA Section 13(1)

DPDPA Section 13(1)DPDPA Section 13(2)+7
Vendor and Processor Governance Under DPDPA
Enterprise

Vendor and Processor Governance Under DPDPA

Contractual Controls, Statutory Boundaries and Operational Accountability for Third-Party Data Processing

"The Data Processor shall process personal data only in accordance with the instructions of the Data Fiduciary and shall not process such personal data for any purpose other than the purpose for which it was provided."

— DPDPA Section 8(2)

DPDPA Section 8(1)DPDPA Section 8(2)+7
Legitimate Uses Without Consent Under DPDPA
Regulatory

Legitimate Uses Without Consent Under DPDPA

Navigating Section 7 Grounds, Operational Boundaries and the Limits of Non-Consensual Processing

"A Data Fiduciary may process the personal data of a Data Principal for certain legitimate uses including the performance of any function under any law, compliance with any order or judgment, or for responding to a medical emergency."

— DPDPA Section 7

DPDPA Section 7(a)DPDPA Section 7(b)+6
Board-Level Privacy Governance Under DPDPA
Strategy

Board-Level Privacy Governance Under DPDPA

Penalty Exposure, Governance Structures and Strategic Oversight for Data Protection Compliance

"The penalty for failure to take reasonable security safeguards to prevent personal data breach shall be up to two hundred and fifty crore rupees."

— DPDPA Schedule, Item 1

DPDPA Section 33DPDPA Schedule+6
Data Retention and Erasure Under DPDPA
Compliance

Data Retention and Erasure Under DPDPA

Navigating Retention Limitations, Erasure Obligations and the Intersection with Sectoral Retention Laws

"The Data Fiduciary shall, unless retention is necessary for compliance with any law for the time being in force, erase personal data upon the Data Principal ceasing to be a customer or withdrawing consent."

— DPDPA Section 8(7)

DPDPA Section 8(7)DPDPA Section 12(3)+8
What DPDP Rules G.S.R. 846(E) Mean for Your India Operations
International

What DPDP Rules G.S.R. 846(E) Mean for Your India Operations

A Section-by-Section Operational Map of the DPDP Rules, 2025 for Foreign Businesses Operating in India

"The Central Government hereby makes the following rules, namely:— 1. Short title and commencement.— (1) These rules may be called the Digital Personal Data Protection Rules, 2025."

— G.S.R. 846(E), Gazette of India, 13 November 2025

DPDPA Section 40DPDP Rules 2025 Rule 3+14
View DPDP Rules Deep Dive
DPDPA Compliance Roadmap for Foreign Companies Entering India
International

DPDPA Compliance Roadmap for Foreign Companies Entering India

A 12-Phase Operational Framework from Entity Assessment to Enforcement Readiness

"This Act applies to the processing of digital personal data within the territory of India where the personal data is collected in digital form or in non-digital form and digitised subsequently."

— DPDPA Section 3(a)

DPDPA Section 3DPDPA Section 5+13
View Foreign Company Hub
Section 8(2) Data Processor Agreements: What Foreign Entities Must Mandate
Contracts

Section 8(2) Data Processor Agreements: What Foreign Entities Must Mandate

Building DPDPA-Compliant Processor Contracts That Survive Board Scrutiny

"A Data Fiduciary shall engage, appoint or use a Data Processor to process personal data on its behalf only under a valid contract."

— DPDPA Section 8(2)

DPDPA Section 8(2)DPDPA Section 8(3)+8
View Vendor Processor Governance
DPDPA's Long-Arm Jurisdiction: When Your Offshore Entity Becomes an Indian Data Fiduciary
International

DPDPA's Long-Arm Jurisdiction: When Your Offshore Entity Becomes an Indian Data Fiduciary

Section 3(b) Extraterritorial Application and Its Implications for Global Corporate Structures

"This Act applies to the processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India."

— DPDPA Section 3(b)

DPDPA Section 3(b)DPDPA Section 3(a)+13
View Extraterritorial Applicability
Data Privacy Due Diligence in India M&A: The DPDPA Dimension
International

Data Privacy Due Diligence in India M&A: The DPDPA Dimension

How DPDPA Transforms Pre-Acquisition Privacy Audits, Warranty Frameworks, and Post-Close Integration

"Every person who has been a Data Fiduciary shall, after ceasing to be so, comply with the obligations under this Act in respect of the personal data processed by that person while being a Data Fiduciary."

— DPDPA Section 8(8)

DPDPA Section 8(8)DPDPA Section 8(2)+14
View M&A Data Privacy Guide

Grounded in Statute

Every insight is anchored to specific provisions of the Digital Personal Data Protection Act, 2023 and the DPDP Rules 2025. Cross-references enable direct verification against authoritative legislative text.

Insights & Answers

What practitioners and boards are asking

What are the consent requirements under DPDPA?

Section 6 requires free, specific, informed, unconditional, and unambiguous consent with clear affirmative action. Section 5 mandates itemised notice before or at the time of data collection. Section 7 provides certain legitimate uses (historically termed deemed consent) including employment, public interest, and medical emergencies. Consent must be as easy to withdraw as to give under Section 6(4).

What is the breach notification requirement under DPDPA?

Section 8(6) requires every Data Fiduciary to inform both the Data Protection Board and each affected Data Principal of a personal data breach. Rule 7 of DPDP Rules 2025 prescribes the form and manner of notification. Rule 7 requires intimation to the Board and affected Data Principals without delay, and a detailed report to the Board within 72 hours of becoming aware of the breach (or any longer period the Board allows).

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Insights?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Insights under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Insights under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Insights?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Insights rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Insights?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.